Keeping Open Source Code Safe: 5 Tips for the Enterprise

1 | 2 | 3 | 4 | 5 | 6 | 7
Next Keeping Open Source Code Safe: 5 Tips for the Enterprise-6 Next

Beware 'The Grim Breachers'

They can kill your brand and deplete your cash. One way to keep "The Grim Breachers" at bay is to know your code. Only by having visibility into the open source code in your applications and containers can you have the control you need to secure and manage that code. It seems straightforward, but 99 percent of Black Duck on-demand scan audits find unknown open source. And the "2015 Future of Open Source" survey showed that more than 55 percent of companies lack policies for open source use; more than 50 percent were unhappy with visibility into security vulnerabilities and only 16 percent have automated code approval process.

Although 95 percent of organizations rely on open source for at least some part of their operations, most companies don't have accurate information about the open source they're using, nor if their open source has any known security vulnerabilities. What's required is automation for visibility and control, identifying and mapping inventory to all known open source security vulnerabilities, providing comprehensive license compliance information, and issuing alerts if any new known vulnerabilities are found. It's important to know your code.

With more than 4,000 security vulnerabilities reported each year – nearly half of them in open source software – it is imperative to know your code. Enterprises need to continuously monitor open source inventory, detect known vulnerabilities and receive alerts as new vulnerabilities that may impact the business are discovered.

Less than half of the respondents to the Black Duck Software "2015 Future of Open Source" survey reported having adequate policies and procedures in place to assure a secure open source selection and approval process. Without this, enterprises cannot truly know their code and lack the necessary visibility and control of open source to secure and manage their environments.

Black Duck Software conducts nearly 1,000 on-demand code scans each year and every scan identifies open source software that the organization did not know it was using. In this slideshow, Black Duck has identified five tips enterprises should consider when trying to keep open source code safe.


Related Topics : Unisys, Stimulus Package, Security Breaches, Symantec, Electronic Surveillance

More Slideshows

PAM PAM Solutions: Critical to Securing Privileged Access

To protect the company from those insiders who abuse their privileged access and from hackers with stolen credentials, many companies are turning to a privileged access management (PAM) solution. ...  More >>

Fake news How Can We Fix the Fake News Problem?

Is fake news a security issue? Some say yes, as it can be used as a social engineering tool to spread disinformation and conceivably to get unsuspecting users to click on malicious links. ...  More >>

blockchain The World According to Blockchain

Blockchain comes with many costs and is surrounded by confusion. Here, we examine realistic use cases, drawbacks and the potential of blockchain. ...  More >>

Subscribe Daily Edge Newsletters

Sign up now and get the best business technology insights direct to your inbox.